Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

MODIFY articles about OAuth since we are moving to net.thunderbird://

Open
#188 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Documentation
Clarity
Needs clarification
Activity status
Quiet

Research direction

Review the existing OAuth articles and the linked Bugzilla reports 2024725 and 2019793 first. Document how multiple Thunderbird instances and release channels interact with the net.thunderbird:// scheme, plus Passkey support on macOS, Windows, and Linux; done means the affected articles cover both listed topics.

Written by the indexing model from the issue text.

Description

Desktop

Copy/pasted from @freaktechnik 's comment in #187

I think we'll also have a big round of prompts with Bug 2024725 - add a custom scheme application handler for OAuth redirects.

  • Scheduled for 152 tentatively
  • Description of bug 2024725:
    • One problem to be aware of is that this will cause issues with systems that have multiple instances of Thunderbird installed—only one application can be associated with the protocol, so if it's associated with the user's copy of release Thunderbird, it will fail if they try to log in on their copy of beta. If all the relevant providers permit unlimited custom schemes, one possible way to mitigate this is by using distinct schemes for the different channels (thunderbird://, tb.beta://, tb.daily://, tb.build://, etc.), which would address the most common scenario, if not the underlying problem.
  • The ability to open a system browser was added in 150 under the following Bug 2019793: add ability to use system browser for OAuth flow
    • Comment 1: By opening the OAuth login page in a browser, we can listen for a request and send the URI with parameters back to the normal flow on our end. This allows existing browser sessions to be usable as authentication, and enables passkey support on macOS for default localhost redirect targets (notably circumventing the conflict between Google's anti-custom redirect stance and macOS's callback design). The new behavior is behind a pref that is enabled for testing builds,but https redirect targets will continue to use the prior flow regardless.
Possible things to document
  • document what happens with running multiple Thunderbird instances e.g. beta and monthly or monthly and ESR
  • what exactly is supported for Passkeys for macOS and Windows and linux
Dominant language
No language data
Stars
7
Forks
1
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from thunderbird/knowledgebase-issues

All issues in thunderbird/knowledgebase-issues

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.